Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2558 | Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in the ability of users to inject arbitrary HTML/JS. This vulnerability is fixed in 1.15.0. |
Github GHSA |
GHSA-cf72-vg59-4j4h | Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature) |
Tue, 03 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Khoj
Khoj khoj |
|
| CPEs | cpe:2.3:a:khoj:khoj:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Khoj
Khoj khoj |
Wed, 21 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in the ability of users to inject arbitrary HTML/JS. This vulnerability is fixed in 1.15.0. | |
| Title | Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-21T19:52:35.357Z
Reserved: 2024-08-12T18:02:04.965Z
Link: CVE-2024-43396
Updated: 2024-08-21T19:52:31.205Z
Status : Analyzed
Published: 2024-08-20T21:15:14.897
Modified: 2024-09-03T18:19:33.167
Link: CVE-2024-43396
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA